Senior Product Security Engineer – Contract

🔥 12 hours ago

🇺🇸 United States – Remote

⏳ Contract/Temporary

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 12%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Iru

Iru

201 - 500 employees

🔒 Cybersecurity

☁️ SaaS

🤝 B2B

💰 $100M Series D on 2024-08

Cybersecurity • SaaS • B2B

Iru is an AI-powered security platform that unifies identity, endpoint, and compliance controls into a single SaaS solution. It offers passwordless workforce identity, endpoint management, endpoint detection & response (EDR), vulnerability management, and compliance automation driven by its Iru AI and Context Model to provide continuous evidence collection and adaptive controls. Iru is designed for IT and security teams at organizations seeking to replace fragmented tooling with a single, integrated system to secure users, apps, and devices while improving operational efficiency.

📋 Description

• Embed security into the product development lifecycle • Identify security risks early and partner with development teams on remediation • Perform security design and architecture reviews for new products and features • Conduct threat modeling for applications, APIs, and AI-enabled services • Review application security posture throughout the SDLC • Review authentication, authorization, and access control implementations • Perform manual web, API, thick-client, and mobile application penetration testing • Validate findings from third-party penetration tests • Conduct secure code reviews • Verify remediation of security vulnerabilities • Drive adoption of secure coding practices • Help define Product Security standards and engineering guardrails • Develop reusable security patterns and reference architectures • Triage findings from SAST, DAST, SCA, container scanning, and cloud security tools • Track remediation SLAs and security metrics • Assess AI-enabled products for security risks • Review LLM integrations and AI workflows • Test AI applications for prompt injection, data leakage, insecure tool use, model abuse, and authorization weaknesses • Help define secure AI engineering standards • Improve automation of security testing throughout CI/CD • Integrate security tooling into developer workflows • Build scripts and tooling that reduce manual security work • Collaborate with Product, Engineering, Infrastructure, Cloud Security, and Compliance teams • Support customer security questionnaires related to product security • Assist Sales Engineering with security discussions when needed

🎯 Requirements

• 5+ years in Product Security or Application Security • Strong understanding of modern application architectures • Experience securing web applications, APIs, microservices, and cloud-native applications • Experience performing threat modeling • Experience conducting penetration testing • Strong understanding of OWASP Top 10 • Strong understanding of OWASP API Top 10 • Strong understanding of authentication and authorization • Strong understanding of OAuth / OIDC • Strong understanding of Secure SDLC • Experience with SAST, DAST, SCA, and container security • Experience partnering directly with engineering teams • Strong written and verbal communication skills • Experience securing AI/LLM applications preferred • Experience with Kubernetes and containers preferred • Familiarity with cloud security (AWS, Azure, or GCP) preferred • Experience with GitHub Actions or CI/CD security preferred • Experience using Snyk, Burp Suite Pro, Semgrep, Wiz, or GitHub Advanced Security preferred • Security certifications such as OSCP, GWAPT, GWEB, CSSLP, or CISSP are a plus

🏖️ Benefits

• Competitive salary • 100% individual and dependent medical + dental + vision coverage • 401(K) with 4% company match • 20 days PTO • Iru Wellness Week the first week in July • Equity for full-time employees • Up to 16 weeks of paid leave for new parents • Paid Family and Medical Leave • Exciting opportunities for career growth

Apply Now

Similar Jobs

🔥 16 hours ago

SYNCREON

10,000+ employees

🚘 Automotive

📦 Logistics

🚗 Transport

Mainframe security consultant providing zSecure Audit and vulnerability management services. Securing z/OS environments through RACF controls, STIG hardening, and vulnerability remediation.

🕒 5 days ago

3Core Systems, Inc

51 - 200

🤝 B2B

💼 Consulting

👥 HR Tech

Senior Azure Cloud Security Engineer securing enterprise Azure infrastructure, identities, applications, and data. Implementing Azure security controls, monitoring, automation, and compliance.

🕒 5 days ago

futureproof consulting

1 - 10

💼 Consulting

📣 Marketing

🔒 Cybersecurity

OT Security Architect defining IEC 62443-aligned cybersecurity standards and architectures. Leading segmentation, governance, and secure integration for regulated manufacturing environments.

🕒 September 5

Arctiq

201 - 500

💼 Consulting

🏥 Healthcare

📦 Logistics

Application Security Remediation Engineer remediating Wiz findings across enterprise applications for Arctiq’s technology services clients. Securing code, dependencies, containers, and DevSecOps delivery pipelines.

🕒 September 5

Handshake

501 - 1000

💼 Consulting

🏥 Healthcare

📦 Logistics

Cybersecurity red teamer testing Handshake AI models for malware, exploit, and attack-chain generation. Handshake AI builds evaluation data and benchmarks for frontier AI labs.